Methods for restricting resources used by an application based on a base profile and an application specific profile

In response to a request for launching an application within an operating system of a data processing system, one or more extended entitlements are extracted from the application, where the one or more extended entitlements specify one or more resources the application is entitled to access. One or...

Full description

Saved in:
Bibliographic Details
Main Authors Martel, Pierre-Olivier J, Yancey, Kelly B, Hagy, Richard L
Format Patent
LanguageEnglish
Published 26.02.2019
Subjects
Online AccessGet full text

Cover

Loading…
More Information
Summary:In response to a request for launching an application within an operating system of a data processing system, one or more extended entitlements are extracted from the application, where the one or more extended entitlements specify one or more resources the application is entitled to access. One or more security profile extensions corresponding to the one or more extended entitlements are dynamically generated. A security profile specifically for the application is created based on the one or more security profile extensions and a base security profile that has been previously compiled, where the base security profile specifies a list of a plurality of base resources. The application is then launched in a sandboxed operating environment that is configured based on the security profile specifically generated for the application.
Bibliography:Application Number: US201715663432